azure-role-selector

Warn

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: MEDIUMPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill's YAML frontmatter identifies the author as "Microsoft," which contradicts the provided author context of "vinayaklatthe." This represents deceptive metadata poisoning that could lead users to misattribute the origin and authority of the skill's instructions.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) as it interprets untrusted user data to provide architectural advice.
  • Ingestion points: User scenarios describing access requirements provided during the interaction.
  • Boundary markers: Absent; the instructions do not implement delimiters or system-level instructions to ignore embedded commands in user scenarios.
  • Capability inventory: None; the skill is documentation-based and does not utilize any executable scripts or subprocess tools.
  • Sanitization: No input validation or escaping logic is present for user-provided data.
  • [SAFE]: External links provided in the "Microsoft Learn" section point to official, well-known documentation domains (learn.microsoft.com) and do not represent a security risk.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 13, 2026, 06:54 PM
Security Audit — agent-trust-hub — azure-role-selector